Pairwise DID Permission Delegation via Cryptographic Signatures

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Centralized identity management systems are burdensome and prone to fraud in delegating permissions, requiring manual processes that lack security and efficiency.

Innovation Solution

A decentralized system using pairwise DIDs allows computing systems to securely and automatically delegate permission scopes between DID owners based on relationships, utilizing cryptographic technologies and distributed ledgers to record and validate these delegations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized identity management systems are used for permission delegation, then security is maintained through centralized control, but the system becomes burdensome and prone to fraud with manual processes

Engineering Contradiction:
ImprovesecurityVSAvoidmanual processes
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces manual mechanical processes with automated cryptographic systems. Permission delegations are automatically verified using cryptographic proofs and blockchain validation, eliminating manual identity verification processes while maintaining security through decentralized cryptographic authentication mechanisms

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces blockchain as an intermediary layer that mediates between identity providers and permission requesters. The blockchain network validates permission delegations through distributed consensus and cryptographic verification, removing the need for centralized identity management intermediaries while enhancing security through decentralization

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If centralized identity management systems are used, then identity verification can be performed, but the system requires intermediaries that reduce privacy and increase complexity

Engineering Contradiction:
Improveidentity verificationVSAvoidcentralized infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the identity verification function from centralized identity management systems and relocates it to the decentralized blockchain network. Individual users maintain their own identity credentials off-chain, while the blockchain only stores and verifies cryptographic proofs, separating identity data storage from verification functionality and reducing centralized infrastructure complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent enables users to self-manage their identity credentials and permission delegations without centralized control. Users generate their own cryptographic key pairs, store credentials in personal wallets, and autonomously verify permission proofs, eliminating the need for centralized identity management infrastructure while simplifying the overall system architecture

Inventive Principle:
Principle #25Self-service

3Productivity

If manual permission delegation processes are used, then centralized control is maintained, but security is reduced and efficiency is lowered

Engineering Contradiction:
ImproveefficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent replaces manual permission delegation processes with automated cryptographic verification. Permission proofs are cryptographically generated and automatically validated by the blockchain network, eliminating manual review processes while enhancing security through cryptographic immutability and distributed validation

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements preliminary cryptographic binding between identity credentials and permission scopes. Permission delegations are pre-signed with cryptographic keys and anchored to the blockchain before actual access is needed, enabling instant verification and execution without manual approval processes while maintaining security through pre-established cryptographic trust

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4111663B1Delegation using pairwise decentralized identifier
Publication Date: 2025.06.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4111663B1 patent drawingFigure 1
  • EP4111663B1 patent drawingFigure 2
  • EP4111663B1 patent drawingFigure 3

AI summary

Delegating a scope of permission between pairwise DIDs. First, a computing system determines a relationship between the first DID and a second DID. The first DID and the second DID are pairwise DIDs. Based on the relationship, the computing system delegates a scope of permission owned by the first DID to the second DID. In particular, the computing system defines the scope of permission, grants a public key of the second DID the scope of the permission. The delegation of the defined scope of permission is signed by a private key of the first DID, such that the signature is a proof of the delegation. A portion of data related to the delegation is then propagated onto the distributed ledger.